User login denial of service in github.com/google/fscrypt
Moderate severity
GitHub Reviewed
Published
Feb 26, 2022
to the GitHub Advisory Database
•
Updated Mar 31, 2023
Description
Published by the National Vulnerability Database
Feb 25, 2022
Published to the GitHub Advisory Database
Feb 26, 2022
Reviewed
Mar 1, 2022
Last updated
Mar 31, 2023
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above
References